Global privacy notice

Privacy Notice

This notice explains how Keski-Suomen Otto ja Pano Oy handles personal data about website visitors, business contacts, quote requesters, and customers worldwide.

1. Who is responsible

Keski-Suomen Otto ja Pano Oy, trading as Odoo Upgrade Done, is the controller for the personal data described in this notice.

Business ID: 2376890-1
Address: c/o Joona Heino, Herneaho 84, FI-41120 Puuppola, Finland
Email: support@odooupgradedone.com

We have not appointed a data protection officer because our present processing does not require one. Privacy requests may be sent to the email above.

2. Two different privacy roles

We act as controller for website use, enquiries, quote and project contacts, contracts, security, billing, and our own business records. This Privacy Notice covers that activity.

When a business customer gives us an Odoo database, filestore, addons, or related project files containing personal data, the customer ordinarily decides why that data exists and how it is used. For that Customer Personal Data, the customer is controller and we are processor. The Data Processing Agreement governs that work. Individuals whose data is inside a customer's Odoo system should normally contact that customer first.

3. Data we collect

We do not receive full payment-card numbers. Stripe or another payment provider collects payment credentials under its own privacy notice.

4. Why we use data and the legal basis

Where we rely on legitimate interests, we consider the business context, necessity, and effect on individuals. You may object as described below. Where we rely on consent, you may withdraw it at any time without affecting earlier lawful processing.

5. When data is required

A work email, migration versions, sufficient project information, and acceptance of the Service Terms are required to submit a quote request. Contract, billing, and tax data are required to place and pay an Order. If you do not provide required data, we may be unable to quote or deliver. Marketing and analytics consent are optional and have no effect on the service.

6. Who receives data

We disclose personal data only as reasonably needed to:

Our current Customer Personal Data service providers are listed on the Subprocessors page. Google receives analytics and advertising measurement data only after consent. Stripe and similar payment providers may act as independent controllers for payment, fraud-prevention, and legal-compliance purposes.

We do not sell personal data. We do not share personal data for cross-context behavioural advertising and do not use Customer Content for advertising.

7. International transfers

We are established in Finland and primarily process project data in the European Union. Some website, communications, analytics, or payment providers may process limited data in other countries. Those countries may have different privacy laws.

Where a restricted transfer mechanism is required, we use an adequacy decision, the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum or another lawful safeguard, plus supplementary measures where appropriate. A copy of the relevant safeguard may be requested, subject to necessary redactions. Global customers may send business and project data to Finland subject to their local transfer requirements and the DPA.

8. Retention

We may retain a record longer when reasonably necessary for litigation, a legal hold, fraud prevention, or a binding legal obligation. When deletion from an encrypted backup cannot occur immediately, the data is isolated from ordinary use and expires under the backup cycle.

9. Your choices and rights

Depending on where you live, you may have rights to access, obtain a copy, correct, delete, restrict, or object to processing; withdraw consent; request portability; and complain to a regulator. Some rights have legal exceptions. We will not discriminate against you for exercising a privacy right.

Send a request to support@odooupgradedone.com. Describe the right and the data involved. We may ask for information reasonably needed to verify identity and authority. If the request concerns personal data inside a customer's Odoo system, identify that customer; we will refer or assist under the DPA.

Use the unsubscribe link in marketing email or contact us to opt out. Use Cookie settings to change your analytics and advertising cookie consent.

10. EEA, United Kingdom, and Switzerland

Individuals in these regions have the GDPR-style rights described above. You may complain to the supervisory authority where you live or work. Our lead authority in Finland is the Office of the Data Protection Ombudsman. You are not required to contact us before complaining, although we welcome the chance to resolve the issue.

11. United States state privacy disclosures

For residents of US states with applicable comprehensive privacy laws, the categories collected, sources, purposes, and recipients are described in sections 3–6. In the preceding 12 months, we may have collected identifiers, internet/network activity, commercial information, professional information, communications, and inferences limited to project needs. We do not sell personal data, share it for cross-context behavioural advertising, or use it for targeted advertising. We do not use sensitive personal information to infer characteristics.

Where applicable, you may request access, correction, deletion, portability, or confirmation of processing, and may opt out of sale, targeted advertising, sharing, or qualifying profiling. Because we do none of the latter activities, no separate opt-out is needed. We use advertising cookies to measure our own advert performance only, with ad personalisation switched off, which is why no targeted-advertising opt-out applies. We honour recognised browser Global Privacy Control signals by keeping all optional cookies off for that browser unless you later choose otherwise.

California residents may use an authorised agent. We will verify the request and the agent's authority as permitted by law. If we deny a request and your state provides an appeal right, reply to the denial within 30 days with “Privacy appeal”.

12. Brazil and other regions

Where Brazil's LGPD applies, the controller is identified in section 1 and the purposes and legal bases are in section 4. You may request confirmation, access, correction, anonymisation, blocking, deletion, portability where regulated, information about sharing, review of consent, and other rights provided by the LGPD, and may contact Brazil's national data protection authority.

Residents of Canada, Australia, New Zealand, and other countries may exercise the access, correction, complaint, consent, and deletion rights available under their local law by contacting us. We apply the controls in this notice globally even where a local rule is less prescriptive.

13. Automated decisions and children's data

We do not make decisions producing legal or similarly significant effects about individuals solely by automated means. The service is for business customers and is not directed to children. Do not submit children's data unless it is necessary for an approved project, lawfully collected, and disclosed to us in advance under section 11 of the Service Terms.

14. Security

We use access restrictions, encryption in transit, protected object storage, confidentiality controls, data minimisation, and deletion procedures appropriate to the risk. Customer files are uploaded using time-limited direct storage links. No system can be guaranteed completely secure; please report a suspected issue to support@odooupgradedone.com.

15. Changes

We may update this notice as the service, providers, or law changes. The effective date above identifies the current version. We will provide additional notice when a change materially affects active customers or consent choices.